Back to skill

Security audit

Warren Website Deploy(mainnet)

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it handles a real wallet private key and sends irreversible mainnet transactions with avoidable key-handling and dependency risks.

Review before installing. Use only a dedicated low-balance deployment wallet, avoid the --private-key argument, avoid putting real keys directly in shell commands, and install dependencies in a clean environment without PRIVATE_KEY set. Expect every deployment, prerequisite mint, and uploaded content to be public, permanent, and paid from your wallet.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
setup.sh:5
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
/dev/null 2>&1 npm install ethers ``` ### Technical Analysis The setup script installs `ethers` without specifying an exact version and without using a committed lockfile. Consequently, each installation may resolve a different package version and dependency graph from the npm registry. Although no evidence indicates that the current `ethers` package is malicious, mutable dependency resolution creates a supply-chain exposure. If the package, one of its transitive dependencies, or associated registry metadata is compromised, running the setup script could install attacker-controlled code. npm lifecycle scripts may execute during installation unless explicitly disabled. This is especially sensitive because the application is designed to run in an environment containing `PRIVATE_KEY`, a wallet credential capable of authorizing irreversible blockchain transactions. ### Attack Path 1. An attacker compromises a future `ethers` release, a transitive dependency, a maintainer account, or relevant npm registry metadata. 2. A user runs `bash setup.sh`. 3. `npm install ethers` resolves the currently published version rather than a previously reviewed and locked version. 4. npm downloads and installs the compromised package graph. 5. Malicious lifecycle code executes during installation, or malicious runtime code executes when `deploy.js` imports `ethers`. 6. The malicious code reads accessible environment variables or modifies transaction behavior. 7. If `PRIVATE_KEY` is present, the attacker may exfiltrate it or use it to sign unauthorized transactions. ### Impact Assessment Successful exploitation would execute code with the privileges of the user running `setup.sh` o ...[truncated 532 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
deploy.js:318
Finding

Wallet Private Key Accepted Through Command-Line Arguments

Content
View full analysis
Wallet private key (or set PRIVATE_KEY env) ``` ### Technical Analysis The program permits the wallet private key to be supplied as a command-line argument. Command-line arguments are commonly exposed through operating-system process inspection, shell history, audit systems, crash diagnostics, terminal-session recording, job schedulers, and observability tooling. The key is not explicitly printed by the reviewed JavaScript code. Nevertheless, accepting it through `process.argv` places it in channels outside the application's control and weakens the documentation claim that the private key is never logged. A blockchain private key is a bearer credential. Possession generally enables arbitrary signing as the wallet owner, rather than access limited to this deployment operation. ### Attack Path 1. A user invokes the supported interface with a literal key, for example: ```bash node deploy.js --private-key 0x... --file ./site.html ``` 2. The shell may save the command in history, and the operating system exposes the argument in the process command line while the program is running. 3. A local user, administrator, monitoring agent, CI log collector, audit service, or other process with sufficient access reads the recorded command line. 4. The observer extracts the private key. 5. The attacker imports the key into another wallet or signing utility. 6. The attacker signs unauthorized transactions, transfers wallet assets, or i ...[truncated 779 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Obfuscated Code

High
Category
Supply Chain
Confidence
50% confidence
Finding

Code contains obfuscation (base64, hex encoding with execution). This is often used to hide malicious functionality.

Content

Scanner excerpt · page_bytecode.js (reported line 14)May include surrounding context.

js
* To reproduce: cd foundry-app && forge build
 * Then: cat out/Page.sol/Page.json | jq -r .bytecode.object
 */
module.exports = '0x60a0604052346100e45761025c80380380610019816100fc565b9283398101906020818303126100e4578051906001600160401b0382116100e4570181601f820112156100e4578051906001600160401b0382116100e85761006a601f8301601f19166020016100fc565b92828452602083830101116100e457815f9260208093018386015e8301015280518060401b6bfe61000180600a3d393df3000161fffe8211830152600b8101601583015ff09182156100d7575260805260405161013a908161012282396080518181816044015260d50152f35b63301164255f526004601cfd5b5f80fd5b634e487b7160e01b5f52604160045260245ffd5b6040519190601f01601f191682016001600160401b038111838210176100e85760405256fe6080806040526004361015610012575f80fd5b5f3560e01c9081634822da1c146100c357506357de26a414610032575f80fd5b346100bf575f3660031901126100bf577f00000000000000000000000000000000000000000000000000000000000000006020608060405180935f19813b0164ffffffffff16905f6021830191601f8501903c808252016040810193846040528385528051938491826060850152018383015e5f828483010152603f1992601f8019910116810103010190f35b5f80fd5b346100bf575f3660031901126100bf577f00000000000000000000000000000000000000000000000000000000000000006001600160a01b03168152602090f3fea2646970667358221220fe4f8a378a0b003d3e1438e45234630293b1a4f7cf94a9f28a4c2d2531789b9d64736f6c634300081a0033';

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill requires access to a highly sensitive secret (PRIVATE_KEY) and instructs the agent to perform real blockchain transactions, but it declares no explicit tool scope such as permissions or allowed-tools. That mismatch weakens policy enforcement and reviewability: an agent platform may not clearly constrain or surface the secret and execution requirements, increasing the risk of unintended secret exposure or unauthorized spending if the skill is invoked in the wrong context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script performs an on-chain side effect beyond the advertised deployment task by automatically minting a prerequisite NFT if the wallet lacks one. In this skill context, the agent uses its own wallet and pays real mainnet gas, so auto-minting can cause unexpected transactions, costs, and asset/state changes without explicit user approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Allowing the private key to be passed on the command line exposes it to shell history, process listings, audit logs, and orchestration telemetry. In this skill context, that is especially dangerous because the key controls a funded wallet used for irreversible mainnet transactions, so accidental disclosure can directly lead to wallet compromise and fund theft.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The header comment says the script is self-contained with no external dependencies besides ethers.js, but it imports local compiled bytecode from './page_bytecode.js' and later help text references running 'bash setup.sh'. This does not match the documented claim of being self-contained with only ethers.js required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.